View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0005091 | OXID eShop (all versions) | 4.04. Security | public | 2013-04-30 11:44 | 2014-07-29 13:06 |
| Reporter | fcos | Assigned To | |||
| Priority | high | Severity | minor | Reproducibility | always |
| Status | resolved | Resolution | fixed | ||
| Product Version | 4.6.5 revision 49955 | ||||
| Target Version | 4.7.14 / 5.0.14 | Fixed in Version | 4.9.0_5.2.0_beta1 | ||
| Summary | 0005091: Newsletter force_sid=x | ||||
| Description | If you subscribe for an newsletter with no active session, the doubleoptin mail has force_sid=x, this cause some critical problem like changed user baskets... seems like it should be fixed in https://bugs.oxid-esales.com/view.php?id=1610 but i can reproduce always has anyone an hotfix for this? | ||||
| Tags | No tags attached. | ||||
| Theme | All | ||||
| Browser | All | ||||
| PHP Version | any | ||||
| Database Version | any | ||||
| related to | 0001610 | resolved | alfonsas_cirtautas | URL params with "sid" in name are interpreted as session ID and replaced with "sid=x" automatically |